# Improper Handling of Exceptional Conditions (CWE-755) The product does not handle or incorrectly handles an exceptional condition. **Stack:** JavaScript - Prevalence: Średnia Pokryto 3 języków - Impact: Wysoki 1 reguł o wysokim poziomie - Prevention: Udokumentowane 4 przykładów poprawek **OWASP:** Insecure Design (A04:2021-Insecure Design) - #4 ## Description When exceptional conditions are not properly handled, the product may enter an undefined state, crash, or expose sensitive information. This can lead to denial of service, information disclosure, or unexpected behavior. ## Prevention Strategie zapobiegania dla Improper Handling of Exceptional Conditions oparte na 1 regułach detekcji Shoulder. ### JavaScript Use finally blocks to release resources (connections, file handles) on all code paths ## Warning Signs - [MEDIUM] Resource at ... may not be released when exceptions occur - [MEDIUM] code that allocates resources (files, connections, memory) within try blocks but fails to release th ## Consequences - DoS - Odczyt danych aplikacji - Wykonanie nieautoryzowanego kodu ## Mitigations - Przewiduj wszystkie możliwe sytuacje wyjątkowe i odpowiednio je obsługuj - Stosuj bloki try-catch i właściwe mechanizmy obsługi błędów - W razie wyjątku zawiódź w bezpieczny sposób ## Detection - Total rules: 4 - Languages: go, javascript, typescript, python ## Rules by Language ### Javascript (1 rules) - **Resource Exhaustion via Exception Handling** [MEDIUM]: Detects code that allocates resources (files, connections, memory) within try blocks but fails to release them in finally blocks or error paths. When exceptions occur, resources may not be properly cleaned up, leading to resource exhaustion, memory leaks, and denial of service. - Remediation: Use finally blocks or try-with-resources pattern: ```javascript // ✅ SAFE - Cleanup in finally let connection; try { connection = await db.getConnection(); await connection.query(sql); } catch (error) { logger.error('Query failed:', error); throw error; } finally { if (connection) { await connection.release(); } } ``` ### Typescript (1 rules) - **Resource Exhaustion via Exception Handling** [MEDIUM]: Detects code that allocates resources (files, connections, memory) within try blocks but fails to release them in finally blocks or error paths. When exceptions occur, resources may not be properly cleaned up, leading to resource exhaustion, memory leaks, and denial of service. - Remediation: Use finally blocks or try-with-resources pattern: ```javascript // ✅ SAFE - Cleanup in finally let connection; try { connection = await db.getConnection(); await connection.query(sql); } catch (error) { logger.error('Query failed:', error); throw error; } finally { if (connection) { await connection.release(); } } ```